memU Privacy Policy
Effective date: September 20, 2026 (Singapore Time)
Last updated: September 20, 2026 (Singapore Time)
1. Scope and who we are
This Privacy Policy explains how NEVAMIND AI PTE. LTD. (“memU,” “we,” “us,” or “our”) collects, uses, stores, discloses, transfers, and deletes personal data in connection with:
memu.soandmemu.pro;- MemU Cloud, Cloud APIs, management pages, and dashboards;
- memU command-line tools, SKILLs, host-Agent adapters, and SDKs; and
- related support, security, and operational services
(collectively, the “Services”).
This Policy applies to the hosted Services operated by memU. A local or self-hosted deployment, a host Agent, or another service selected and operated by you is subject to the privacy practices of the person or organization operating it.
By registering for or using the Services, you acknowledge this Policy. New users must affirmatively agree to this Policy and the memU Terms of Service before completing registration.
2. Important privacy and security notices
Before using MemU Cloud, you should understand the following material practices and limitations:
- Cloud content is not encrypted at rest. Memory, Search History, update records, complete API-key copies, embeddings, indexes, and related stored data are currently stored in a form that memU systems can read and process. They are not end-to-end encrypted or encrypted at rest.
- Complete API keys are stored in plaintext. This allows an authenticated user to view a key again and allows installation instructions to be generated in real time. Anyone who obtains an active key may be able to read, search, submit, or modify Memory associated with the account.
- Host Agents decide what becomes Memory. A host Agent or local CLI may process local conversations, tool-call records, or session information when preparing Memory. The current MemU Cloud design receives the resulting Agent-prepared Memory rather than the underlying raw session data, but the prepared Memory may contain personal, confidential, or sensitive information from that data.
- External vectorization is used. Plaintext Memory segments and Agent-prepared retrieval requests are sent to Voyage AI or another external vectorization provider.
- There is no backup or bulk-export guarantee. The standard Service does not promise backup, restoration, recovery, bulk export, migration, or data portability. You should keep independent copies of information you cannot afford to lose.
- Deletion is permanent. Individual Memory deletion and account closure cannot be undone. There may be no backup from which deleted content can be restored.
Do not submit passwords, private keys, authentication tokens, financial credentials, or information that applicable law or another obligation requires to be encrypted at rest. Review the permissions granted to host Agents and regularly review the Memory stored in your account.
3. Personal data we collect
The data we collect depends on how you use the Services.
3.1 Account and contact data
We collect information used to create, authenticate, maintain, and support your account, such as:
- your email address and account identifier;
- authentication and account-status information;
- communications and support requests you send to us; and
- information you provide when requesting account recovery, exercising a privacy right, reporting a security issue, or appealing an enforcement decision.
The standard Service currently supports email-based login and personal accounts. If you cannot access the email account used to register, we may request additional evidence to verify that you own or control the account before changing access.
3.2 API-key and credential data
For each active API key, memU stores:
- the complete plaintext key;
- an irreversible hash used for routine authentication;
- a user-assigned name, if provided;
- creation, last-use, and expiration information; and
- operational information needed to validate and manage the key.
Installation instructions containing a key are generated in real time and are not retained as a separate installation-instruction record. When you revoke or delete a key, its stored plaintext copy and corresponding hash are deleted immediately, and the key becomes invalid for subsequent authentication attempts. An operation accepted before revocation may still complete.
3.3 Memory and other user content
MemU Cloud receives and stores Memory prepared and submitted by a host Agent, CLI, SDK, API client, or user. Memory may include summaries, preferences, instructions, facts, workflows, Markdown content, Skills, metadata, and other information selected for later retrieval.
A host Agent or local CLI may process raw conversations, messages, tool-call records, or local session information on your device to prepare Memory. Under the current Cloud design, the underlying raw session information is not uploaded as raw session data. Only the resulting Memory is submitted. However, an Agent may reproduce or summarize information from a session in the Memory it creates, including personal or sensitive information.
You are responsible for deciding what may lawfully and appropriately be processed through the Services and for obtaining any notices, permissions, consents, or other legal bases needed for personal data relating to another person.
3.4 Search History
When an Agent or CLI retrieves Memory, MemU Cloud stores the Agent-prepared retrieval request as Search History so that you can review, troubleshoot, and audit activity through the management page. The stored request reflects the Agent's interpretation of what it needs to retrieve and is not necessarily text written directly by you.
Search History may include:
- the retrieval time;
- the complete Agent-prepared retrieval request; and
- related account, Memory, or operational identifiers needed to associate and present the record.
Under the current design, Search History does not store matched Memory content or snapshots, similarity scores or ranking, Agent type, or the operation result. Specific metadata fields may change as the Services evolve.
3.5 Memory update records
When Memory is updated, memU may store an update record for review and troubleshooting. Under the current design, an update record preserves the Memory content as it existed before the update. It does not preserve both the before-and-after content in the same snapshot.
Deleting or changing the current Memory does not rewrite an existing update record. An update record may therefore continue to contain the earlier Memory content until the record is deleted under the retention practice described in Section 8.
3.6 Usage and behavioral statistics
We collect limited operational data to operate, secure, measure, and improve the Services. Raw usage records currently include:
- event time;
- client or software version;
- Agent type;
- operating-system type;
- operation type;
- error type; and
- a user identifier used to deduplicate daily active users.
These behavioral statistics do not include API keys or API-key identifiers, IP addresses, additional device information, Memory identifiers, token counts, Memory text, retrieval-query text, or retrieved Memory content.
3.7 Cookies and local storage
Our web interfaces may use cookies, local storage, or similar technologies needed for authentication, session continuity, security, and user-interface preferences. We do not currently use a third-party analytics platform to store or process the usage and behavioral statistics described in Section 3.6.
4. How we use personal data
We use personal data for the following purposes:
- creating, authenticating, maintaining, recovering, suspending, terminating, or closing accounts;
- issuing, displaying, validating, expiring, revoking, and deleting API keys;
- receiving, storing, segmenting, embedding, indexing, retrieving, displaying, editing, and deleting Memory;
- storing and presenting Search History and update records;
- operating Agent, CLI, API, SDK, and management-page functionality;
- providing support and responding to questions, complaints, privacy requests, security reports, and appeals;
- detecting, investigating, preventing, and responding to fraud, abuse, attacks, service misuse, and security incidents;
- monitoring reliability, diagnosing errors, planning capacity, and improving compatibility and product performance;
- enforcing our Terms of Service and protecting users, memU, and others;
- complying with legal obligations, valid legal process, and lawful governmental requests;
- communicating material service, security, legal, or policy changes; and
- completing a reorganization, financing, merger, acquisition, sale, or similar corporate transaction, subject to applicable law.
We process data only for purposes that are reasonably related to providing, securing, operating, improving, and administering the Services, purposes you separately authorize, and purposes permitted or required by applicable law.
Where applicable law requires a particular legal basis, processing may be based on your consent, performance of our agreement with you, compliance with a legal obligation, protection of vital interests, or our legitimate interests or those of another person, provided that those interests are not overridden where the law provides otherwise.
5. Model training, human review, and product improvement
memU does not use private Memory, raw Agent history, retrieval requests, or retrieved results to train models operated by memU or another party. We do not intentionally provide those materials to a third party for that party's model training.
We may use the limited usage statistics described in Section 3.6 to guide product strategy and improve reliability, compatibility, retrieval quality, and performance. We may also use aggregated statistics that cannot be linked to an individual for product analysis, capacity planning, reliability improvement, business planning, and publication of overall Service usage or activity trends.
memU personnel do not routinely inspect private Memory, retrieval requests, Search History, or update records. We will not use plaintext content for troubleshooting, evaluation, or analysis unless you first provide additional, affirmative, purpose-specific authorization. We will explain the intended purpose and will not expand that use beyond your authorization.
This restriction does not prevent automated processing needed to provide the Services. It also does not prevent limited access where reasonably necessary to protect the Services, investigate suspected unlawful use or abuse, respond to a security incident or emergency, comply with law or valid legal process, or respond to a valid government request.
6. External vectorization and service providers
MemU Cloud divides Memory into segments and creates vector embeddings and index structures so that relevant Memory can be retrieved. For Cloud vectorization, memU currently sends the following plaintext to Voyage AI (voyageai.com):
- Memory text segments; and
- retrieval requests prepared and submitted by a host Agent or CLI.
We do not intentionally attach your username, email address, API key, or other account identity fields to text sent for vectorization. However, if Memory or a retrieval request contains a name, email address, identifier, confidential information, or other personal data, that information will be sent as part of the text.
memU uses external providers to deliver the Services and does not intentionally submit user data for model-training purposes. We have not verified a contractual promise from the current vectorization provider concerning model-training exclusion, zero retention, a specific retention period, or processing only in a specified region. External providers operate under their own systems, practices, terms, and contractual obligations, and memU cannot guarantee every aspect of their data handling.
We may also use infrastructure, hosting, security, communications, monitoring, and other service providers that process information on our behalf as necessary to provide and protect the Services. We seek to limit provider access and processing to the applicable service purpose and legal requirements.
Providers may change as the Services evolve. We may update this Policy, provider disclosures, or service documentation to reflect a change. We do not promise a separate notice solely because a supplier changes, but we will provide notice or obtain consent where applicable law requires it or where the change otherwise requires renewed consent.
7. When we disclose personal data
We may disclose personal data:
- to service providers and subprocessors that host, vectorize, secure, monitor, support, or otherwise help operate the Services;
- at your direction or with your separate authorization;
- to investigate and respond to suspected unlawful activity, abuse, fraud, security threats, or serious harm;
- to courts, regulators, law-enforcement bodies, government agencies, or other authorities where required or permitted by applicable law or valid legal process;
- to professional advisers, auditors, insurers, and counterparties subject to appropriate confidentiality obligations; or
- in connection with a proposed or completed reorganization, financing, merger, acquisition, sale, insolvency, or transfer of all or part of the business or assets associated with the Services.
When exceptional access or disclosure is required for legal, governmental, security, abuse-prevention, or emergency purposes, we seek to limit it to information reasonably necessary for that purpose. We will notify the affected user where permitted and reasonably practicable. Notice may be delayed or omitted where prohibited by law, where it could compromise an investigation or security response, or where prior notice cannot reasonably be given in an emergency.
memU does not sell private Memory or other private user content, and we do not license it to third parties for their independent use.
8. Retention
Retention periods are operational expectations rather than guarantees that data will be retained for a minimum or maximum period.
8.1 Memory
While your MemU Cloud account remains active, memU does not proactively delete stored Memory under its ordinary retention practice. This is not a guarantee of permanent storage, integrity, availability, backup, export, or recovery.
8.2 Search History
Search History is ordinarily expected to be retained for approximately three months. Operational circumstances may cause us to retain it for longer or delete it earlier, including where a user's data volume is high.
Users cannot currently delete individual Search History entries or clear all Search History. Search History is maintained as an activity record, subject to our ordinary retention practice, applicable law, and account closure.
8.3 Update records
Update records are ordinarily expected to be retained for approximately 90 days. Technical or operational circumstances may cause us to delete them earlier or retain them longer.
8.4 Raw usage statistics
Raw usage and behavioral statistics are expected to be retained for approximately 90 days. We may delete them earlier for operational or other reasons.
After raw records are deleted, we may retain aggregated statistics that cannot be traced or linked back to a specific user. We remove user identifiers and do not retain a mapping intended to reconnect the aggregate result to an individual. We will not attempt to re-identify data aggregated or de-identified in this manner. These aggregate statistics may be retained for the long term and are not deleted merely because an account is closed.
8.5 Account, support, security, and legal records
Account information is generally retained while the account remains active and during the account-deletion process. Support, security, complaint, enforcement, and legal records may be retained for as long as reasonably necessary to address the applicable request, incident, dispute, legal obligation, or legitimate operational purpose.
We may preserve, restrict, isolate, disclose, or otherwise process limited information for longer where required by law, valid legal process, a governmental or regulatory requirement, security needs, dispute resolution, or prevention of serious harm.
9. Deletion and account closure
You can review and edit Memory through the management page. Supported management controls also allow you to delete an individual Memory.
When an individual Memory deletion succeeds, memU immediately deletes the current Memory record, its text segments, embeddings, and vector-index entries. This does not rewrite or delete:
- Search History, which does not currently store matched Memory content; or
- update records, which may contain the Memory content as it existed before an update.
Those records remain until deleted under Section 8 or through account closure.
When you close your MemU Cloud account:
- all associated API keys become invalid immediately;
- memU begins asynchronously deleting account-associated data from ordinary production systems, including Memory, segments, embeddings, indexes, Search History, update records, stored API-key plaintext and hashes, account data, and raw usage records still linked to you; and
- the operational target is ordinarily to complete deletion within approximately three days.
Actual deletion may finish earlier or later because of data volume and technical, operational, security, or legal circumstances. The three-day period is a target, not a guaranteed deadline or a promise to retain data for three days. Deletion may begin immediately and cannot be undone.
After account closure, data awaiting asynchronous deletion is no longer ordinarily associated with an active user account. Memory or a historical snapshot may still identify you or another person if the content itself includes identifying information.
MemU Cloud does not currently maintain separate Service backups or a routine isolated legal-hold store for Memory, Search History, or update records. If a valid legal or governmental requirement requires preservation or different handling, we may preserve or process the limited information required for the necessary period.
Uninstalling a local CLI, SKILL, host-Agent integration, scheduled task, or configuration does not close your Cloud account or delete Cloud data. Account suspension, termination, or closure also does not automatically remove local software, configuration, cache, Memory, environment variables, or API-key copies from your devices. You are responsible for deleting local copies you no longer need.
10. International processing and transfers
MemU Cloud's primary infrastructure is hosted in the AWS Tokyo Region (ap-northeast-1), and most processing performed by memU's own Cloud environment occurs there.
Data sent to Voyage AI or another service provider may be processed, retained, or transferred in other countries or regions selected by that provider. Your data may therefore be processed outside your country of residence and outside Singapore.
Where required by applicable law, we take steps intended to ensure that an overseas recipient provides a standard of protection comparable to that required by applicable data-protection law or that another lawful transfer mechanism or exception applies.
11. Security
Network communications between supported CLI or web clients and MemU Cloud use HTTPS. Communications between MemU Cloud and external vectorization providers also use HTTPS.
Cloud content is currently not encrypted at rest. Complete active API keys are also retained in plaintext so they can be displayed again through the authenticated management page. HTTPS protects data in transit but does not change these storage practices.
Access to production systems is limited to authorized service-operations personnel for legitimate operational, security, support, or legal purposes. Production access is logged and subject to periodic review under our internal security controls. Permission to access infrastructure does not by itself authorize personnel to inspect private content.
No method of transmission, storage, or security is completely secure. You are responsible for protecting your email account, API keys, local configuration, environment variables, devices, and host-Agent permissions. Promptly revoke an exposed API key and notify support@nevamind.ai if you suspect unauthorized access or another security incident.
If a personal-data breach occurs, we will assess it and provide notifications to affected individuals and regulators where required by applicable law.
12. Your choices and rights
Depending on applicable law and subject to lawful exceptions, you may have rights to:
- request access to personal data we hold about you and information about how it has been used or disclosed;
- request correction of inaccurate or incomplete personal data;
- withdraw consent to processing based on consent, with reasonable notice;
- object to or request restriction of certain processing;
- request deletion of certain personal data;
- close your account;
- receive information about the consequences of withdrawing consent; and
- submit a complaint to memU or an applicable data-protection authority.
The management page provides direct controls for reviewing and editing Memory, deleting individual Memory, managing API keys, and closing an account. It does not currently provide deletion of individual or all Search History entries or a guaranteed bulk export.
Some requests may be limited or refused where an exception applies, where fulfilling the request would disclose another person's data, compromise security or an investigation, conflict with a legal obligation, or be technically infeasible under applicable law. We may ask you to verify your identity before fulfilling a request.
Withdrawal of consent or deletion of data needed to provide the Services may prevent us from continuing to provide some or all of the Services. To make a privacy request, contact support@nevamind.ai.
13. Children and eligibility
memU does not impose a separate universal minimum age. Users must satisfy the minimum-age, parental-consent, supervision, and other requirements that apply to the host Agent or platform through which they use memU and the requirements of applicable law.
If you believe a child has provided personal data in violation of applicable law, contact support@nevamind.ai. We may request information needed to evaluate the report and take legally required action.
14. Third-party and self-hosted services
Host Agents and platforms—including Codex, Claude Code, OpenClaw, and other supported or connected products—are independent services. Their terms, privacy policies, model behavior, permissions, and data practices apply separately. memU does not control what local information a host Agent reads, how it interprets memU instructions, or what content it chooses to include in Memory.
In local or self-hosted mode, you or the person operating the deployment selects and controls the storage, embedding provider, environment, credentials, infrastructure, retention, and security settings. This Policy does not describe the independent processing performed by a self-hosted operator or a third-party provider selected directly by you.
Links to third-party sites and services do not mean that memU controls or endorses their privacy practices.
15. Aggregated and de-identified information
We may create aggregate or de-identified information from Service usage. We remove direct user identifiers and do not retain a mapping intended to reconnect aggregated results to a specific person.
We may use and retain such information for internal analysis, capacity planning, reliability improvement, product strategy, and business planning, and may publish overall usage or activity trends. Where a small group or narrow breakdown could reasonably permit indirect identification, we will combine, generalize, suppress, or refrain from publicly disclosing that breakdown.
We will not attempt to re-identify information that has been aggregated or de-identified as described in this section.
16. Changes to this Policy
We may review and update this Policy as the Services, our business, suppliers, risk controls, market conditions, or applicable law change. When we update it, we will revise the Last updated date at the beginning of the Policy.
If a change is material, we may provide notice through the Services, by email, or through another reasonable channel, or require renewed consent, depending on the nature of the change and applicable law. Changes required for legal, regulatory, security, fraud-prevention, or urgent operational reasons may take effect immediately.
Where renewed consent is not required, continued use of the Services after a revised Policy takes effect means that you acknowledge the revised Policy to the extent permitted by applicable law. We will provide notice or obtain consent where applicable law requires it.
17. Contact
Questions, privacy requests, consent withdrawals, complaints, security reports, and concerns about this Policy or our handling of personal data may be sent to:
NEVAMIND AI PTE. LTD.
Privacy and Data Protection Contact
Email: support@nevamind.ai
We may request information reasonably necessary to verify your identity, locate the relevant account or data, and protect personal data from unauthorized disclosure before acting on a request.
18. Relationship with the Terms
This Policy should be read together with the memU Terms of Service. This Policy explains our handling of personal data; the Terms govern use of the Services. If a separate written agreement applies to your use of memU, its data-protection terms control to the extent of a conflict, subject to applicable law.
The English version of this Policy controls if a translation conflicts with it, except where applicable law requires otherwise.